[12288] in Commercialization & Privatization of the Internet
Re: Clipper and Ames....
daemon@ATHENA.MIT.EDU (Doug Humphrey)
Sat May 14 03:25:31 1994
Date: Fri, 13 May 1994 13:02:19 -0400 (EDT)
From: Doug Humphrey <digex@ss1.digex.net>
To: Barry Shein <bzs@world.std.com>
Cc: mo@uunet.uu.net, com-priv@psi.com
In-Reply-To: <199405090516.AA11042@world.std.com>
On Mon, 9 May 1994, Barry Shein wrote:
>
> Yes, one of the cardinal rules of security: Don't make it any more
> expensive to break your security than it costs to bribe one of your
> "trusted" staff, it's just wasted effort.
>
> What I wonder is whether there is any provision in this whole Clipper
> thing to compel the-powers-that-be to inform those potentially
> affected that their keys may have been compromised?
There are established procedures for dealing with super sensitive
information; certain pieces of information dealing with nuclear
weapons in the field units come to mind... The levels of oversight
(the good kind ;-) are pretty extreme there, and the cost-per-piece-
of-info is very high, but there is not that much information in the
clipper situation (the number of keys isn't the issue; it would be
the number of times that the key data bases are accessed, which
should be quite small in any legit operation).
Would the justice department and the fbi have the experience and
will to pull this off like the armed forces do? Not on your life.
So, get the military and the civilians to have joint custody?
They would never go for it...
Doug